daytona-windows-cert
test on Windows, enterprise CA, corporate certificate, GPO cert, TLS fetch failed, Windows sandbox, daytona windows, self-hosted cert. Use when validating iPolloWork Windows enterprise TLS/OS-trust fixes in a Daytona Windows sandbox.
pinned to #c2d3a52updated 2 weeks ago
Ask your AI client: “install skills/daytona-windows-cert”.
Requires the metahub MCP server installed in your client. Set up MCP.
mh install skills/daytona-windows-certmetahub onboarded this repo on the author's behalf.
If you own github.com/Devin-AXIS/iPolloWork on GitHub, claim the listing to take over publishing. Your claim preserves the existing eval history and badges; only the curator label is replaced with verified-publisher on your next publish.
Stars
1,202
Last commit
2 weeks ago
Latest release
published
- #a2a-protocol
- #ai-agent-network
- #bnb-chain
- #ethereum
- #mcp-server
- #protocol
- #smart-contracts
- #token-economy
- #web3
- #x402-compatible
About this skill
Pulled from SKILL.md at publish time.
Run the verified Windows repro for iPolloWork enterprise TLS behavior: install a fake corporate CA into the Windows machine store, serve healthy and broken HTTPS control planes, install a Windows build, and prove the desktop app and spawned runtimes use the operating system trust path.
Evaluation report
WarningsAutomated checks the publisher passed at publish time — structure, docs, safety, and whether the artifact behaves as claimed.c2d3a52· 2 weeks ago
Kind-specific
31Skill: SKILL.md present
found at .opencode/skills/daytona-windows-cert/SKILL.md · frontmatter source: SKILL.md
Skill: body content present
1,518 words · 12,395 chars · 12 sections · 26 code blocks
Skill: triggers declaredwarn
No `trigger` phrases in SKILL.md frontmatter
Add `trigger:` lines so Claude knows when to activate this skill — e.g. `when building MCP servers` or `for diagram creation`.
Skill: allowed-tools scope
no allowed-tools restriction (Claude may use anything)
Release history
1- releasecurrentc2d3a52warn2 weeks ago
Contents
Skill: Daytona Windows Enterprise Certificate Test
Run the verified Windows repro for iPolloWork enterprise TLS behavior: install a fake corporate CA into the Windows machine store, serve healthy and broken HTTPS control planes, install a Windows build, and prove the desktop app and spawned runtimes use the operating system trust path.
Use this as the Windows companion to daytona-electron-test. Use fraimz when
the result needs frame-by-frame proof, screenshots, or PR evidence. Reuse the
repo support assets instead of copying their logic: scripts/support/setup-ipollowork-tls-repro.ps1,
scripts/support/ipollowork-doctor.ps1, and docs/support/enterprise-network-doctor.md.
When to use
- User says "test on Windows", "Windows sandbox", or "daytona windows".
- User is validating an enterprise CA, corporate certificate, GPO cert, or self-hosted cert path on Windows.
- User reports
TLS fetch failed,fetch failed, or a certificate-specific failure when connecting iPolloWork to a self-hosted control plane. - User needs to prove the Windows app uses OS trust and spawned runtimes receive
the OS trust bundle via
NODE_EXTRA_CA_CERTS.
Prereqs
- Daytona CLI must be at least the API version. The verified CLI was v0.194:
brew upgrade daytonaio/cli/daytona
brew link --overwrite daytona
daytona version
ghmust be authenticated toDevin-AXIS/iPolloWorkand able to create/delete temporary public prereleases.- Have a Windows iPolloWork build or installer ready. Keep secrets and customer materials out of the temporary release asset.
1. Create the Windows sandbox
Windows sandboxes are VM-only and are created from Daytona's prebuilt windows
snapshot. Available classes are windows-small (1 vCPU / 4 GB),
windows-medium (2 vCPU / 8 GB), and windows-large (4 vCPU / 16 GB). The
verified path used windows-medium:
daytona create --snapshot windows-medium
The command prints a sandbox ID and a web terminal URL. Save the ID once:
SANDBOX_ID="<SANDBOX_ID>"
Windows sandboxes may auto-stop. Restart the sandbox before continuing:
daytona sandbox start <ID>
Use the saved shell variable for later commands:
daytona sandbox start "$SANDBOX_ID"
2. exec vs VNC (the session-0 trap)
Important: daytona ssh <ID> is interactive-only and fails from scripts on
the host-key prompt. Use this shape for setup commands instead:
daytona exec <ID> -- <cmd>
For example:
daytona exec "$SANDBOX_ID" -- whoami
daytona exec runs as nt authority\system in Windows session 0. That is useful
for admin setup, but it cannot see the interactive VNC user's app UI, and
$env:APPDATA resolves to the SYSTEM profile, not C:\Users\Administrator.
Do not inspect app UI state, userData, or installed app settings through SYSTEM
profile paths.
Human GUI access is: Daytona Dashboard -> sandbox -> ⋮ menu -> VNC ->
Connect. Use exec for setup and logs; use VNC to drive the installed iPolloWork
app and observe the user-visible result.
3. Get the app build in
For large Windows builds, zip the build, attach it to a temporary public
prerelease, and download it inside the VM with the Windows-bundled curl.exe
and tar. The curl.exe 8.x and tar binaries ship in the Windows image.
From the repo root on the host, stage a zip that expands under C:\ow. Include
the app build plus the support scripts from this repo so the VM reuses the
checked-in harness:
TAG="ipollowork-win-cert-repro-$(date +%Y%m%d%H%M%S)"
ZIP="/tmp/${TAG}.zip"
# Put your Windows app build under /tmp/ipollowork-win-cert-upload/ipollowork/app
# and include scripts/support/setup-ipollowork-tls-repro.ps1 plus
# scripts/support/ipollowork-doctor.ps1 under ipollowork/scripts/support/.
# Include .opencode/skills/daytona-windows-cert/scripts/ca-probe.js as
# ipollowork/ca-probe.js.
ditto -c -k --keepParent /tmp/ipollowork-win-cert-upload/ipollowork "$ZIP"
gh release create "$TAG" "$ZIP" --repo Devin-AXIS/iPolloWork --prerelease
The release command shape from the verified session was:
gh release create <tag> <zip> --repo Devin-AXIS/iPolloWork --prerelease
Download and extract inside Windows:
DOWNLOAD_URL="https://github.com/Devin-AXIS/iPolloWork/releases/download/${TAG}/$(basename "$ZIP")"
daytona exec "$SANDBOX_ID" -- cmd /c 'mkdir C:\ow 2>NUL'
daytona exec "$SANDBOX_ID" -- cmd /c "curl.exe -L -o C:\ow\app.zip $DOWNLOAD_URL"
daytona exec "$SANDBOX_ID" -- cmd /c 'tar -xf C:\ow\app.zip -C C:\ow'
The Windows download/extract shape from the verified session was:
daytona exec "$SANDBOX_ID" -- cmd /c 'curl.exe -L -o C:\ow\app.zip <release-download-url>'
daytona exec "$SANDBOX_ID" -- cmd /c 'tar -xf C:\ow\app.zip -C C:\ow'
If the zip only contains the app, fetch the support scripts from the same branch instead of rewriting them:
daytona exec "$SANDBOX_ID" -- cmd /c 'mkdir C:\ow\ipollowork\scripts\support 2>NUL'
daytona exec "$SANDBOX_ID" -- cmd /c 'curl.exe -L -o C:\ow\ipollowork\scripts\support\setup-ipollowork-tls-repro.ps1 https://raw.githubusercontent.com/Devin-AXIS/iPolloWork/dev/scripts/support/setup-ipollowork-tls-repro.ps1'
daytona exec "$SANDBOX_ID" -- cmd /c 'curl.exe -L -o C:\ow\ipollowork\scripts\support\ipollowork-doctor.ps1 https://raw.githubusercontent.com/Devin-AXIS/iPolloWork/dev/scripts/support/ipollowork-doctor.ps1'
4. Stand up the enterprise-TLS repro
scripts/support/setup-ipollowork-tls-repro.ps1 creates a fake corporate root and
intermediate, trusts the root in Cert:\LocalMachine\Root, maps
poc.ipollowork.test to localhost, and serves:
https://poc.ipollowork.test:8443— healthy chain.https://poc.ipollowork.test:9443— broken chain with the intermediate removed.
Do not run the listeners only inside a one-off daytona exec; the PowerShell
listeners die when that exec session closes. Persist them with a scheduled task
that runs as SYSTEM and keeps the session alive:
ENCODED=$(python3 - <<'PY'
import base64
script = r'''
$ErrorActionPreference = "Stop"
$repo = "C:\ow\ipollowork"
$cmdPath = "C:\ow\start-ipollowork-tls-repro.cmd"
$cmd = @"
@echo off
cd /d "$repo"
powershell -NoProfile -ExecutionPolicy Bypass -File scripts\support\setup-ipollowork-tls-repro.ps1
powershell -NoProfile -ExecutionPolicy Bypass -Command "while (`$true) { Start-Sleep -Seconds 3600 }"
"@
Set-Content -LiteralPath $cmdPath -Value $cmd -Encoding ASCII
schtasks /create /f /sc onstart /ru SYSTEM /tn iPolloWorkTlsRepro /tr $cmdPath
schtasks /run /tn iPolloWorkTlsRepro
'''
print(base64.b64encode(script.encode("utf-16le")).decode())
PY
)
daytona exec "$SANDBOX_ID" -- powershell -NoProfile -ExecutionPolicy Bypass -EncodedCommand "$ENCODED"
Verify the healthy listener is up:
daytona exec "$SANDBOX_ID" -- cmd /c 'netstat -ano | findstr :8443'
Optional diagnostic output from the checked-in doctor script:
daytona exec "$SANDBOX_ID" -- powershell -NoProfile -ExecutionPolicy Bypass -File 'C:\ow\ipollowork\scripts\support\ipollowork-doctor.ps1' -WebUrl https://poc.ipollowork.test:8443 -ApiUrl https://poc.ipollowork.test:9443 -ExpectedIssuerMatch "iPolloWork TLS Repro"
5. Verify the fix
Probe Electron's view of the Windows machine store
Copy .opencode/skills/daytona-windows-cert/scripts/ca-probe.js into the VM as
C:\ow\ca-probe.js. Its contents are intentionally small and reusable:
daytona exec "$SANDBOX_ID" -- cmd /c 'copy C:\ow\ipollowork\ca-probe.js C:\ow\ca-probe.js'
const { X509Certificate } = require("node:crypto");
const tls = require("node:tls");
const needle = (process.env.IPOLLOWORK_TLS_REPRO_CA_MATCH || "iPolloWork TLS Repro").toLowerCase();
function countMatchingSubjects(certificates) {
let count = 0;
for (const pem of certificates) {
try {
const certificate = new X509Certificate(pem);
if (certificate.subject.toLowerCase().includes(needle)) count += 1;
} catch {
// Ignore entries that are not parseable X.509 certificates.
}
}
return count;
}
const system = tls.getCACertificates("system");
const bundled = tls.getCACertificates("default");
const result = {
systemCount: system.length,
reproInSystem: countMatchingSubjects(system),
defaultCount: bundled.length,
reproInDefault: countMatchingSubjects(bundled),
};
console.log(JSON.stringify(result, null, 2));
if (result.reproInSystem === 0) {
process.exitCode = 1;
}
Run Electron in node mode. Adjust the executable path for your unpacked build or installed app:
daytona exec "$SANDBOX_ID" -- cmd /c 'set ELECTRON_RUN_AS_NODE=1 && "C:\ow\ipollowork\app\iPolloWork.exe" C:\ow\ca-probe.js'
The verified result was:
{"systemCount":42,"reproInSystem":6,"defaultCount":150,"reproInDefault":0}
This is the crucial #2562 verification for the GPO/enterprise-CA case: the
Windows system store (LocalMachine\Root) contains the repro corporate CA, while
the bundled Mozilla roots do not.
Verify the installed app via VNC
Drive the installed iPolloWork Windows app through VNC, not daytona exec.
- Open Daytona Dashboard -> sandbox -> ⋮ menu -> VNC -> Connect.
- Launch or install iPolloWork as the interactive user.
- Point the self-hosted/control-plane URL at
https://poc.ipollowork.test:8443. The request should succeed. - Repeat against
https://poc.ipollowork.test:9443. The request should fail with a named certificate/chain error, not a vaguefetch failedbanner.
Use daytona-electron-test for normal Electron driving patterns and fraimz for
captured proof if this is PR evidence.
Verify the app's generated CA bundle path
The real Windows userData folder is:
C:\Users\<User>\AppData\Roaming\com.differentai.ipollowork
It is not C:\Users\<User>\AppData\Roaming\iPolloWork. Because exec runs as
SYSTEM, inspect the interactive user path explicitly:
daytona exec "$SANDBOX_ID" -- cmd /c 'dir "C:\Users\Administrator\AppData\Roaming\com.differentai.ipollowork\system-ca-bundle.pem"'
daytona exec "$SANDBOX_ID" -- cmd /c 'findstr /c:"iPolloWork TLS Repro" "C:\Users\Administrator\AppData\Roaming\com.differentai.ipollowork\system-ca-bundle.pem"'
Known gotcha: system-ca-bundle.pem is written once at first launch and then
memoized. If a CA is added after first launch, restart the app before
expecting it to appear. On real fleets the GPO CA is present at boot, so this
usually does not bite customers.
Shell/quoting gotchas
- zsh strips backslashes in unquoted Windows paths. Quote the whole
cmd /cpayload:
daytona exec "$SANDBOX_ID" -- cmd /c 'dir "C:\Users\Administrator\AppData\Roaming\com.differentai.ipollowork"'
- Pipes and
|insidedaytona exec ... -- powershell -Command '...'can be eaten by the intermediatecmdlayer. Usepowershell -EncodedCommandwith a base64 UTF-16LE payload for anything with pipes or nested quotes:
ENCODED=$(python3 - <<'PY'
import base64
command = r'Get-ChildItem Cert:\LocalMachine\Root | Where-Object Subject -like "*iPolloWork TLS Repro*"'
print(base64.b64encode(command.encode("utf-16le")).decode())
PY
)
daytona exec "$SANDBOX_ID" -- powershell -NoProfile -ExecutionPolicy Bypass -EncodedCommand "$ENCODED"
%ERRORLEVEL%expands at parse time incmdone-liners. Prefer PowerShell and$LASTEXITCODEwhen you need to propagate exit codes:
daytona exec "$SANDBOX_ID" -- powershell -NoProfile -ExecutionPolicy Bypass -Command 'curl.exe --version; exit $LASTEXITCODE'
cmd /cplustimeoutfails with "input redirection is not supported" underdaytona exec. Useping -nfor sleeps:
daytona exec "$SANDBOX_ID" -- cmd /c 'ping -n 6 127.0.0.1 >NUL'
Cleanup
Stop the scheduled repro, remove the certificates/hosts/bindings through the checked-in setup script, delete the sandbox, and delete the temporary prerelease:
daytona exec "$SANDBOX_ID" -- cmd /c 'schtasks /end /tn iPolloWorkTlsRepro'
# Core repro cleanup shape: setup-ipollowork-tls-repro.ps1 -Cleanup
daytona exec "$SANDBOX_ID" -- powershell -NoProfile -ExecutionPolicy Bypass -File 'C:\ow\ipollowork\scripts\support\setup-ipollowork-tls-repro.ps1' -Cleanup
daytona sandbox delete <ID>
gh release delete <tag> --yes
Reviews
No reviews yet. Be the first.
Related
Gpt Researcher
An autonomous agent that conducts deep research on any data using any LLM providers
Verification Before Completion
Evidence before assertions, always
Writing Plans
Turn specs into phased implementation plans
mh install skills/daytona-windows-cert